Alert · reviewed · held
Entity Denied Origin 0 entered the hold band (Skoor 80, n=0): entity.denied, entity.high_risk.
- Detector
- entity_hold
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_4ndrgqqi3r
- Transfer
- —
- Skoor at alert
- 80 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Entity enti_sim_nort_4ndrgqqi3r ("Denied Origin 0"), enrolled under the Northwind Payroll (simulated) program, triggered an entity_hold alert. The entity's Skoor reached 80, placing it in the hold band, with a hard signal present (entity.denied) and an auto-hold applied.
What the evidence shows. The evidence lists two signals: entity.denied (hard signal, weight 60, detail "verification DENIED") and entity.high_risk (weight 20, detail "marked high risk by screening"). The entity record confirms verification status DENIED, high_risk true, and review reasons listing sanctions_match. Last screened 2026-06-24. The n=0 field indicates no transaction volume has been scored alongside this alert; this is an entity-level hold, not a transaction-level hold. Route reason is "hard signal," consistent with autoHold true. Confidence on the evidence record itself is stated as 0.4.
What was checked. Reviewed the alert evidence payload, the entity record (verification status, high-risk flag, review reasons, screening date), the program declaration (Northwind Payroll, ACH, US), and prior dispositions. No prior dispositions exist for this entity. No transaction or transfer record is referenced in this alert, so there is no fund movement tied to this specific alert to release or hold at the transaction level.
What is recommended. This entity carries a sanctions_match review reason alongside a DENIED verification outcome and a high-risk flag. This combination goes beyond a routine hold review and warrants escalation to compliance for a sanctions-specific review before any further onboarding or transaction activity proceeds for this entity. A person should confirm whether the sanctions_match is a true positive and whether related entities or transactions under the Northwind Payroll program require review.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- entity.denied is a hard signal with weight 60, and verification status is confirmed DENIED in the entity record
- review reasons field explicitly lists sanctions_match, which is a category requiring compliance sanctions review rather than routine disposition
- high_risk flag (weight 20) corroborates elevated risk independent of the sanctions reason
- n=0 indicates no transaction data is attached to this alert, so this is an entity-level concern, not a transfer to release
- no prior dispositions exist, so there is no history indicating this was already reviewed and cleared
- evidence confidence is stated as 0.4, which is moderate; this lowers overall confidence in the disposition though the hard signal and sanctions_match reason are unambiguous
Evidence
{
"n": 0,
"band": "hold",
"skoor": 80,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "verification DENIED",
"weight": 60
},
{
"code": "entity.high_risk",
"detail": "marked high risk by screening",
"weight": 20
}
],
"version": "ers-v1",
"autoHold": true,
"confidence": 0.4,
"routeReason": "hard signal"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.